"Source OS" -> firewall logs -> remote syslog?
-
I'm hoping to remotely retrieve "Source OS" data from the firewall logs. Ideally I'd like this turned on for all rules without having to manually edit each one, but currently I've enabled it for a few. Currently, logging gets sent to a remote server via syslog, with raw entries that look like this:
64,,,1458836143,igb0,match,pass,in,4,0x0,,44,1246,0,none,6,tcp,5,1.2.3.4,8.8.8.8,57444,25565,0,S,1296312405,,64240,,mss;nop;wscale;nop;nop;sackOK
For "Source OS" enabled rules that trigger, will the "Source OS" field get appended or inserted before being passed off to syslog for delivery to the remote server?
-
The source OS isn't recorded in the logs as far as I'm aware.
You could set a specific rule to match a specific source OS and then maybe go by whatever that rule's tracking ID is, but the actual OS info won't be in the log data.
https://docs.netgate.com/pfsense/en/latest/monitoring/filter-log-format-for-pfsense-2-2.html